US2025322083A1PendingUtilityA1

Highly-available cryptographic keys

Assignee: AMAZON TECH INCPriority: Dec 4, 2020Filed: Jun 26, 2025Published: Oct 16, 2025
Est. expiryDec 4, 2040(~14.3 yrs left)· nominal 20-yr term from priority
Inventors:Divyesh A. Sah
G06F 21/107G06F 21/629G06F 21/604G06F 21/54H04L 2209/76H04L 63/0435H04L 9/14H04L 9/0822H04L 9/088G06F 21/602
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for providing encrypted cryptographic keys. A system obtains a request to generate a data key. The system generates the data key and a data structure comprising the data key encrypted with keys from a set of compute regions. The system provides the data structure and the data key in response to the request. The data structure can be used to obtain the data key contingent on at least one compute region of the set of compute regions being available.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 one or more processors; and   memory storing computer-executable instructions that, when executed by the one or more processors, cause the system to:
 obtain a request to perform a cryptographic operation, wherein the request comprises one or more encrypted cryptographic keys, identifiers for one or more compute regions associated with the one or more encrypted cryptographic keys, at least one of the compute regions corresponding to a geographic location or region, and one or more preferences indicating one or more criteria for selecting at least one compute region; 
 select at least one compute region from the one or more compute regions based at least in part on the one or more preferences and an availability of the at least one compute region; and 
 provide at least one encrypted cryptographic key of the one or more encrypted cryptographic keys to the selected at least one compute region to perform the cryptographic operation, wherein the provided at least one encrypted cryptographic key is associated with the selected at least one compute region. 
   
     
     
         2 . The system of  claim 1 , wherein the one or more preferences indicate an order of compute regions of a plurality of compute regions to use to perform the cryptographic operation. 
     
     
         3 . The system of  claim 1 , wherein the request to perform the cryptographic operation is a request to obtain a plaintext cryptographic key. 
     
     
         4 . The system of  claim 1 , wherein selecting the at least one compute region comprises transmitting a message to the at least one compute region to determine the availability of the at least one compute region. 
     
     
         5 . The system of  claim 1 , wherein the request is associated with an application programming interface of a cryptography service. 
     
     
         6 . The system of  claim 1 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to:
 generate another request based at least in part on the request, wherein the other request includes an identifier of a managed key from the selected at least one compute region and the at least one encrypted cryptographic key; and   submit the other request to a cryptography service instance of the selected at least one compute region to cause the cryptography service instance to decrypt the at least one encrypted cryptographic key using the managed key from the selected at least one compute region.   
     
     
         7 . The system of  claim 6 , wherein the at least one encrypted cryptographic key is encrypted with the managed key from the selected at least one compute region. 
     
     
         8 . The system of  claim 1 , wherein the at least one encrypted cryptographic key is provided to a cryptography service instance of the selected at least one compute region. 
     
     
         9 . A computer-implemented method, comprising:
 obtaining a request to perform a cryptographic operation, wherein the request comprises one or more encrypted cryptographic keys, identifiers for one or more compute regions associated with the one or more encrypted cryptographic keys, at least one of the compute regions corresponding to a geographic location or region, and one or more preferences indicating one or more criteria for selecting at least one compute region;   selecting at least one compute region from the one or more compute regions based at least in part on the one or more preferences and an availability of the at least one compute region; and   providing at least one encrypted cryptographic key of the one or more encrypted cryptographic keys to the selected at least one compute region to perform the cryptographic operation, wherein the provided at least one encrypted cryptographic key is associated with the selected at least one compute region.   
     
     
         10 . The computer-implemented method of  claim 9 , further comprising:
 generating another request based at least in part on the request, wherein the other request includes an identifier of a managed key from the selected at least one compute region and the at least one encrypted cryptographic key; and   submitting the other request to a cryptography service instance of the selected at least one compute region to cause the cryptography service instance to decrypt the at least one encrypted cryptographic key using the managed key from the selected at least one compute region.   
     
     
         11 . The computer-implemented method of  claim 9 , wherein the one or more preferences indicate an order of compute regions of a plurality of compute regions to use to perform the cryptographic operation. 
     
     
         12 . The computer-implemented method of  claim 9 , wherein selecting the at least one compute region comprises transmitting a message to the at least one compute region to determine the availability of the at least one compute region. 
     
     
         13 . The computer-implemented method of  claim 9 , wherein the request is associated with an application programming interface of a cryptography service. 
     
     
         14 . The computer-implemented method of  claim 9 , further comprising:
 obtaining another request to decrypt the at least one encrypted cryptographic key;   determining the at least one encrypted cryptographic key corresponds to a managed key;   decrypting the at least one encrypted cryptographic key using the managed key to determine a plaintext of the at least one encrypted cryptographic key; and   providing a response to the other request that comprises the plaintext of the at least one encrypted cryptographic key.   
     
     
         15 . A non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to:
 obtain a request to perform a cryptographic operation, wherein the request comprises one or more encrypted cryptographic keys, identifiers for one or more compute regions associated with the one or more encrypted cryptographic keys, at least one of the compute regions corresponding to a geographic location or region, and one or more preferences indicating one or more criteria for selecting at least one compute region;   select at least one compute region from the one or more compute regions based at least in part on the one or more preferences and an availability of the at least one compute region; and   provide at least one encrypted cryptographic key of the one or more encrypted cryptographic keys to the selected at least one compute region to perform the cryptographic operation, wherein the provided at least one encrypted cryptographic key is associated with the selected at least one compute region.   
     
     
         16 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:
 obtain another request to decrypt the at least one encrypted cryptographic key;   determine the at least one encrypted cryptographic key corresponds to a managed key;   decrypt the at least one encrypted cryptographic key using the managed key to determine a plaintext of the at least one encrypted cryptographic key; and   provide a response to the other request that comprises the plaintext of the at least one encrypted cryptographic key.   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 15 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:
 generate another request based at least in part on the request, wherein the other request includes an identifier of a managed key from the selected at least one compute region and the at least one encrypted cryptographic key; and   submit the other request to a cryptography service instance of the selected at least one compute region to cause the cryptography service instance to decrypt the at least one encrypted cryptographic key using the managed key from the selected at least one compute region.   
     
     
         18 . The non-transitory computer-readable storage medium of  claim 15 , wherein the one or more preferences indicate an order of compute regions of a plurality of compute regions to use to perform the cryptographic operation. 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 15 , wherein the request is associated with an application programming interface of a cryptography service. 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 15 , wherein selecting the at least one compute region comprises transmitting a message to the at least one compute region to determine the availability of the at least one compute region.

Join the waitlist — get patent alerts

Track US2025322083A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.